ISO 27001 Consulting Hero Banner
ISO 27001 Consulting

ISO 27001 Consulting and ISMS Certification Readiness

ISO/IEC 27001 is the certifiable international standard for an Information Security Management System. IRM designs and implements your ISMS, runs the risk assessment and internal audit, and gets you audit-ready in 90 days.

  • All 93 Annex A controls
  • Audit-ready in 90 days
  • From $4,250 per month

What is ISO 27001 Consulting?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS): the policies, risk assessment, controls, and management review an organization uses to protect information, certified by an accredited certification body. The 2022 edition sets out the management system requirements in Clauses 4 to 10 and lists 93 Annex A controls across organizational, people, physical, and technological themes. Unlike SOC 2, which is an attestation report, ISO 27001 is a certificate, and it is the credential enterprise and international buyers most often require of a SaaS vendor.

ISO 27001 consulting is the work of getting a company from a set of informal security practices to a certifiable ISMS. IRM scopes the system, runs the gap assessment against all 93 Annex A controls and the Clause 4 to 10 requirements, performs the risk assessment and risk treatment, writes the Statement of Applicability, policies, and procedures, delivers the internal audit and management review a certification auditor asks to see, and manages the Stage 1 and Stage 2 audits. Most SaaS clients with a reasonable technical baseline reach audit-ready within 90 days.

The work is led by a Virtual CISO, so the same person who builds your ISMS also runs it month to month, answers customer security questionnaires with the certificate, and handles the annual surveillance audits. Companies that also need SOC 2 or ISO 42001 get one control set and one evidence library that serves all three; the management system clauses are identical between ISO 27001 and ISO 42001, and SOC 2 shares the large majority of the technical controls.

What the Engagement Includes

  • ISMS scope statement covering locations, systems, services, and interested parties
  • Gap assessment against Clauses 4 to 10 and all 93 Annex A controls with a risk-ranked remediation plan
  • Information security risk assessment methodology, risk register, and risk treatment plan
  • Statement of Applicability (SoA) with justification for every included and excluded control
  • Policy and procedure set written for your stack: access, cryptography, change, supplier, incident, business continuity, secure development
  • Control implementation support across identity, logging, backups, endpoint, cloud configuration, and vendor management
  • Internal audit and management review, delivered and recorded
  • Certification body selection, Stage 1 and Stage 2 audit support, and annual surveillance audit management

When you do not need ISO 27001 Yet

If every buyer who has asked for assurance is in North America and accepts a SOC 2 report, start with SOC 2. It is faster to a first report and the controls carry over to ISO 27001 later. ISO 27001 costs more to maintain than SOC 2 because of the annual surveillance audits and the three-year recertification cycle.

If no customer, investor, or regulator has asked for either, run the free gap assessment, fix the highest-risk controls, and revisit certification at the first enterprise or international deal. Tell us who is asking and for what, and we will tell you which framework to sequence first.

Who ISO 27001 Consulting is for, by ARR Stage

ISO 27001 demand tracks how many of your buyers are enterprise or outside North America. This is how we size engagements for the SaaS companies we work with.

Who ISO 27001 Consulting is for, by ARR Stage
StageTypical ARRWhat You NeedIRM Engagement
Pre-seed and bootstrappedUnder $1M ARRA security policy set and a risk assessment that answer questionnaires credibly; certification is usually premature.Free ISO 27001 gap assessment, then a Crawling tier sprint to close the top 10 gaps and issue the policy set.
Seed$1M to $5M ARRAn operating ISMS aligned to ISO 27001:2022, without certifying yet, so enterprise procurement stops stalling.Walking tier, 90 days to an operating ISMS with the SoA, risk register, and policies in place.
Series A and B$5M to $25M ARRISO 27001 certification, often alongside SOC 2 Type II, plus a supplier risk program buyers will inspect.Walking or Running tier, audit-ready in 90 days, Stage 1 and Stage 2 audits in months 4 to 6.
Growth and PE-backed$25M+ ARRCertified ISMS maintained across products and regions, surveillance audits passed, ISO 27001 plus SOC 2 plus ISO 42001 from one control set.Running tier managed GRC program with a named vCISO and quarterly control reviews.

The 90-Day ISO 27001 Plan

This is the sequence we run to take a SaaS company from no formal ISMS to audit-ready. Stage 1 and Stage 2 certification audits with an accredited body typically follow in months 4 to 6.

Days 1 to 30

Scope and Assess

  • Define the ISMS scope, interested parties, and the context of the organization
  • Gap assessment against Clauses 4 to 10 and all 93 Annex A controls, scored by likelihood and impact
  • Asset inventory, risk assessment methodology agreed, first risk register built
  • Certification body shortlisted and audit dates pencilled in
Days 31 to 60

Design and Document

  • Information security policy, objectives, roles, and the Statement of Applicability approved
  • Risk treatment plan agreed and the highest-risk controls closed: MFA, least privilege, logging, backups, encryption
  • Procedure set issued: access, change, supplier, incident, business continuity, secure development
  • Security awareness training delivered and recorded, supplier requirements added to contracts
Days 61 to 90

Operate and Prove

  • Controls operate for a full cycle: access reviews, vulnerability management, change approvals, supplier reviews
  • Internal audit of the ISMS completed and nonconformities closed
  • Management review held and minuted against the standard's required inputs
  • Certification body engaged and Stage 1 audit scheduled

ISO 27001 Consulting Pricing

ISO 27001 work is delivered as a monthly Virtual CISO subscription, so the certification project and the ongoing ISMS operation use the same engagement and the hours track the work.

Walking tier, Seed stage

From $4,250 per month

20 to 40 hours per month, sprint under 6 months. Excludes certification body audit fees and any compliance automation platform license.

Bootstrapped teams that only need the policy set and a first risk assessment start on the Crawling tier from $2,000 per month (15 to 20 hours). Companies running ISO 27001 with SOC 2 or ISO 42001, or maintaining a certified ISMS through surveillance audits, sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.

See all Pricing Tiers

Check your ISO 27001 Readiness first for Free

Free, no signup, runs in your browser

Free ISO 27001 Gap Assessment

Assess all 93 Annex A controls of ISO/IEC 27001:2022 (118 items with the Clause 4 to 10 requirements), score each gap on a 5x5 risk matrix, and download a remediation roadmap. Your answers stay in your browser.

Run the ISO 27001 Gap AssessmentBook a Free Consultation

Bring the report to your free consultation and we will turn it into a scoped 90-day plan on the call. Related: SOC 2 compliance if your buyers are in North America, ISO 42001 consulting if you ship AI, and Fractional CISO services if you need the leadership as well as the certificate.

floating circle
Frequently Asked Questions

Frequently Asked Questions about ISO 27001 Consulting

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). The 2022 edition specifies the management system requirements in Clauses 4 to 10 (context, leadership, planning, support, operation, performance evaluation, improvement) and lists 93 Annex A controls across organizational, people, physical, and technological themes. It is certified by an accredited certification body and is the security credential enterprise and international buyers most often require.

An ISO 27001 consultant scopes the ISMS, runs the gap assessment against the clauses and the 93 Annex A controls, performs the risk assessment and risk treatment, writes the Statement of Applicability, policies, and procedures, delivers the internal audit and management review, and prepares the organization for the certification body's Stage 1 and Stage 2 audits. IRM delivers this through a Virtual CISO who then keeps the ISMS operating after certification.

IRM's program reaches audit-ready in 90 days for a SaaS company with a reasonable technical baseline: 30 days to scope and assess, 30 to design and document, and 30 to operate the controls and complete the internal audit and management review. The certification body's Stage 1 and Stage 2 audits typically follow in months 4 to 6. Companies with significant infrastructure gaps or multiple sites should plan for 6 to 12 months.

IRM delivers ISO 27001 as a monthly Virtual CISO subscription starting at $4,250 per month on the Walking tier (20 to 40 hours) for a typical certification program, or $2,000 per month on the Crawling tier for a policy set and first risk assessment. Certification body audit fees are additional and depend on the number of employees, sites, and the scope of the ISMS.

ISO 27001 is a certified management system with a defined set of 93 controls, recognized worldwide; SOC 2 is an attestation report by a CPA firm against the AICPA Trust Services Criteria, and is the norm in North America. Both cover similar technical ground (access control, change management, logging, vendor management, incident response), so a company that has one can add the other with mostly documentation and audit work. IRM builds one control set that serves both.

The 2022 edition reorganized Annex A from 114 controls in 14 domains to 93 controls in 4 themes (organizational, people, physical, technological), merged overlapping controls, and added 11 new ones, including threat intelligence, cloud services security, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities, web filtering, and secure coding. Organizations certified to the 2013 edition had to transition by October 2025.

The Statement of Applicability (SoA) is the mandatory document that lists every Annex A control, states whether it is included or excluded from your ISMS, and justifies the decision, usually by reference to the risk treatment plan. It is one of the first documents a certification auditor reads and it ties the risk assessment to the controls actually implemented. IRM writes it with you during days 31 to 60.

No, but platforms such as Vanta, Drata, or Secureframe reduce the evidence-collection effort for the annual surveillance audits and usually pay for themselves above roughly 20 employees. Smaller teams can run an ISMS with a document repository, a control calendar, and a risk register, which is how IRM runs it for clients who are not ready for a platform subscription.

The certificate is valid for three years, with surveillance audits by the certification body in years one and two and a recertification audit in year three. The ISMS has to keep operating between audits: risk reviews, internal audits, management reviews, access reviews, supplier reviews, and awareness training. Under an IRM subscription your Virtual CISO runs that calendar so the audits become routine.

Both use the same harmonized management system structure, so an existing ISO 27001 ISMS provides most of the management system that ISO 42001 requires. ISO 42001 adds AI-specific requirements: AI risk assessment, AI system impact assessment, and its own 38 Annex A controls for the AI lifecycle. IRM integrates the two into one management system for companies that build or deploy AI.

Yes. ISO 27001 is international and accredited certification bodies operate across Canada and the United States. IRM works with SaaS companies across both countries from Toronto and adds the Canadian obligations that usually travel with ISO 27001 for Canadian buyers, PIPEDA and Quebec Law 25 privacy requirements in particular.

Yes. IRM's free ISO 27001 Gap Assessment at irmcon.com/products/iso27001/ assesses all 93 Annex A controls of ISO/IEC 27001:2022 plus the Clause 4 to 10 requirements, scores each gap on a 5x5 risk matrix, and produces a downloadable remediation roadmap. It runs in your browser, and it is the same starting point IRM uses on day one of a paid engagement.
Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.